Security

Last updated: December 2025

At QR Code API, security is a core part of our infrastructure and development practices. This page outlines the security measures we implement to protect your data.

Data Encryption

In Transit

All API communications use TLS 1.3 encryption. We enforce HTTPS on all endpoints and use HSTS headers.

At Rest

Data stored in our databases is encrypted using AES-256. Database backups are also encrypted.

Authentication & Access Control

Infrastructure Security

Rate Limiting & Abuse Prevention

Audit Logging

We maintain comprehensive audit logs of:

Audit logs are retained for 90 days and are available to Enterprise customers.

Privacy by Design

Vulnerability Disclosure

If you discover a security vulnerability, please report it responsibly to security@qrcodeapi.io. We appreciate your help in keeping our platform secure and will acknowledge your contribution.

Compliance

Our infrastructure providers maintain the following certifications:

Contact

For security questions or concerns, contact our security team at security@qrcodeapi.io.